Privacy Policy
Your Privacy
The Caravan Bedding Shop is committed to protecting the privacy of our Website users and customers. We understand the importance of privacy and comply with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA).
This policy explains how we use your personal data for our Products and covers:
Who we are;
Your personal data that we store and how we obtain it;
How we use your personal data;
How and why we share your personal data with others;
How long we retain your data;
Data storage, security and transfers;
Changes to this policy;
Your rights.
If you have any further questions about how we process your information, please do not hesitate to get in touch by contacting our Data Protection Officer:
Address: Data Protection Officer. Email: caravanbeddingshop@yahoo.co.uk
Please be aware that this Privacy Policy no longer applies when following links to any third party websites, and in these instances, users should consult the third party’s Policy.
- Who we are
Our mission at The Caravan Bedding Shop is to make sure everyone can achieve good sleep in their caravan without the luxury price tag.
Any reference to “The Caravan Bedding Shop”, “our”, “us”, “we” and “Company” refers to The Caravan Bedding Shop, the trading name of the website owner and operator.
Definitions:
“Website” – we provide Products and content via our Website https://www.caravanbeddingshop.com
“Website Provider” – our Website is managed and hosted by the third-party WordPress.
“Products” – we offer a range of bedding and mattresses for the leisure vehicle industry
- Your personal data that we store and how we obtain it
Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data: includes first & last name, title, and details of your leisure vehicle
- Contact Data: includes billing address, delivery address, email address and telephone numbers.
- Financial Data: if you make any payments on our Website, over the phone or in our showroom, your credit/debit card details are processed directly by a third-party processor that will store all payment information and transaction details. We will only retain details of transactions on secure servers and we will not retain your credit or debit card information.
- Transaction Data: includes details of Products you have purchased from us.
- Technical Data: includes internet protocol (IP) address, access times, any websites you linked from, pages you visit, the links you use, the ad banners and other content you view, your login data, browser type and version, information about your device, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Website.
- Profile Data: includes your username and password (which are hashed and not visible to The Caravan Bedding Shop), purchases or orders made by you, preferences, feedback and survey responses. We may append data that we have received from third party sources to this data to enrich your profile.
- Usage Data: includes information about how you use our Website and Products.
- Marketing and Communications Data: includes your preferences in receiving marketing from us.
We use different methods to collect data from and about you including through:
- Direct interactions: You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email, visiting our showroom or otherwise. This includes personal data you provide when you:
purchase our Products on our Website, over the phone, email or in our showroom;
create an account on our Website;
agree that marketing can be sent to you;
enter a competition, promotion or survey;
interact with us on social media; or
give us feedback or contact us.
- Automated technologies or interactions: As you interact with our Website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. For more information on how we use cookies see our cookie policy.
- Technical Data from the following parties:
analytics providers;
advertising networks; and
search information providers.
We work with partners who provide us with analytics and advertising. This includes helping us understand how users interact with our marketing and Website to help us improve performance, relevancy and useability. Cookies and similar technologies may be used to collect this information.
Cookies
Cookies are small files containing letters and numbers stored in your browser or the hard drive of your device and it is used to transfer information. You can prevent the setting of cookies by adjusting the settings on your browser or your mobile phone. If you disable or refuse cookies, please note that some parts of this Website may become inaccessible or not function properly.
For more information on how we use cookies see our cookie policy.
- How we use your personal data
We only collect, keep, use or share your information for genuine business purposes in our legitimate interests, when you’ve approved us to do so or when we’re legally obliged to. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you (for example when you buy a Product).
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation.
In limited circumstances, we may request your consent to process your personal data.
Lawful Basis
For The Caravan Bedding Shop to be allowed to process your personal data, we must have a legal basis for the processing. The data protection legislation sets out what these bases are. We have described below the different bases that we rely on and provided examples of the processing.
Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/Product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us. If you do not want us to process any of the personal data we have listed as being processed for legitimate interests, you have the right to object. For more information see the section below relating to your rights. Please note that if you object we may still continue to process your personal data in certain circumstances. Please also remember that if we can’t process your personal data for these purposes your customer experience may not be as enjoyable.
Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract. For example when you buy a Product on our Website, it creates a contract between us. We need to process your personal data that you provide in the order to fulfil our part of the contract and deliver the Products to you. If you do not provide your details we won’t be able to complete your order.
Comply with a legal obligation means processing your personal data where it is necessary for compliance with a legal obligation that we are subject to. For example, if you buy a Product which is an age restricted item (such as a game rated 18) or if there is a Product recall.
Consent means processing your personal data where you have explicitly told us that you will allow us to do so. In some cases, we will ask whether you would like us to process your personal data. For example, when an item is out of stock and you provide your telephone number for us to call to discuss available alternatives or notify you when the out of stock item becomes available. If you provide us with consent, you may withdraw it at any time by contacting us.
Purposes for which we will use your personal data
We only collect, keep, use or share your information for legitimate interests, when you have approved us to do so, or when we are obliged to legally. These purposes are as follows:
Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to you account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and to enable you to post reviews.
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for Products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites.
Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately.
Communicating with you. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you.
- How and why we share your personal data with others
We will never sell information that can be used to personally identify you to a third party. Personally identifiable data will not be shared without user consent. However, we may share and disclose your personal data to certain third parties as set out in the following section.
Information sharing with third-party service providers
We may share personal information about you in respect of our Website and Products with our service providers and partners, which include our ecommerce platform provider (WordPress), CRM provider (Exact Online), our payment service providers (PayPal, Stripe), and email marketing provider (Mailchimp). Through WordPress we use a number of third-party apps to provide services such as the regular back up of data and to manage delivery costs per product. A full list of our third party providers can be obtained from contacting our DPO at caravanbeddingshop@yahoo.co.uk.
We may transfer your personal data outside of the UK and the European Economic Area (EEA) (e.g. WordPress is based in the United States). This will always be in accordance with data protection law, including mechanisms to lawfully transfer data across borders, and subject to strict safeguards.
Anonymised information
We may display on our marketing communications, Website and internal reporting, aggregated and anonymised data that does not personally identify you, but which shows general statistics and trends, for example, survey results and customer review rating.
Legal Disclosures
We may preserve or disclose information about you to comply with a law, regulation, legal process, or governmental request; to assert legal rights or defend against legal claims; or to prevent, detect, or investigate illegal activity, fraud, abuse, violations of our terms, or threats to the security of our Services or the physical safety of any person.
Third Party Purchaser
We may also disclose your personal information in connection with a corporate merger or amalgamation with another entity, a sale of all or a substantial portion of our assets or stock, including as part of any due diligence exercise carried out in relation to the same, provided that the information disclosed continues to be used for the purposes permitted by this Privacy Policy by the entity acquiring the information.
Except as described above, we will never share your personal information with any other party without your consent.
- How long we retain your data
We will keep your personal data for as long as it remains necessary for the identified purpose or as required by law, which may extend beyond the termination of our relationship with you. We may retain certain data as necessary to prevent fraud or future abuse, or for legitimate business purposes, such as analysis of aggregated, non-personally-identifiable data, account recovery, or if required by law.
If you request that your data be removed from our databases, it may not be possible to completely delete all your personal information due to technological and legal constraints and/or if it is necessary for us to retain some or all of it to comply with a legal or regulatory obligation.
- Data storage, security and transfers
We encrypt data transmitted to and from the Website. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorised access. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy.
Your data may be processed or stored via destinations outside of the UK and the European Economic Area (EEA), but always in accordance with data protection law, including mechanisms to lawfully transfer data across borders, and subject to strict safeguards. For example, we work with third parties who help deliver our Services to you, whose servers may be located outside the UK or EEA.
Those safeguards may include the transfer of personal information to countries that have been assessed by the European Commission (EC) as providing an adequate level of protection for personal information. Where we transfer data to companies within the US or elsewhere outside of the EEA we will ensure that appropriate contractual arrangements are in place to protect your personal data which may include standard model clauses in a format approved by the EC.
We use WooCommerce as our ecommerce platform provider in respect of sales of Products via our Website. Where you submit personal data to our Website, WooCommerce acts as a data processor on our behalf and transfers the data through WooCommerce’s servers. Under normal circumstances WooCommerce will use its servers in the Republic of Ireland (WooCommerce International Ltd) for this but on occasion its servers in the USA or in Canada may be used. Your information is then sent to other WooCommerce locations and to service providers who may be located in other regions, including the United States (where WooCommerce is based) and the United States. When WooCommerce sends your personal information outside of the EEA, UK or Switzerland, they do so in accordance with applicable law. You can view their privacy policy here.
We use Exact Online as our order management, inventory management and CRM system. Exact Online acts as a data processor on our behalf and your data is stored securely in data centres within the European Economic Area (EEA). To deliver parts of its service Exact Online may use sub processors which are outline here. You can view Exact Online’s privacy policy.
We use MailChimp as our email service provider and they act as a data processor on our behalf. Their headquarters and servers are in the United States. This means data they process may be transferred to, stored, or processed in the United States. In addition, they use sub processors to provide services and their servers may be located outside of Europe. You can view the list of sub processors here.
Mailchimp has put a number of measures in place to ensure that European data remains protected when it’s transferred outside of Europe. You can access a list of the security measures here.
Where you have chosen a password that enables you to access your personal account, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.
We do not store any credit or debit card information. Payments are processed via a third-party payment provider whose servers are located within either the UK, the EEA or the US that is fully compliant with Level 1 Payment Card Industry (PCI) data security standards. Any payment transactions are encrypted using SSL technology.
- Changes to this policy
We may update this policy from time to time and, if we make any material changes, we will notify you when we do so. We will provide you with the opportunity to review such changes. By continuing to use our Products and Services after the changes have been made and we have notified you of them, the way we use your personal data will be subject to the terms of the updated policy.
- Your rights
As indicated above, whenever we rely on your consent to process your personal data, you have the right to withdraw your consent at any time by unsubscribing from our communications or contacting us.
Under data protection law, you have rights including:
Your right of access: You have the right to ask us for copies of your personal information (also known as a subject access request).
Your right to rectification: You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure: You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing: You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing: You have the right to object to the processing of your personal information in certain circumstances.
Your right to data portability: You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
Your right to not be subject to automated individual decision making: you have the right to not be subject to decisions based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you.
You can control whether or not your personal information is used for marketing: You have the right to withdraw your agreement to the use of your personal information for marketing at any time. You can do this by clicking unsubscribe on one of our marketing emails, you will no longer receive our emails immediately. If you email us to ask us to no longer send you any marketing (by email or SMS) or for your data to be deleted, please allow one calendar month for your request to be processed.
Where you have asked us to erase your personal information, please note that it may not be possible to completely delete all your personal information due to technological and legal constraints and/or if it is necessary for us to retain some or all of it in order to comply with a legal or regulatory obligation.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you. We may ask you to provide us with identification so that we can be sure that we are dealing with the right person. This is a security measure. We may also contact you to ask you to put your request into writing and/ or for further information in relation to your request to speed up our response.
Please contact us at caravanbeddingshop@yahoo.co.uk if you wish to make a request.
Contacting The Information Commissioner’s Office
If you are not happy with how we have dealt with your personal data or your enquiries relating to that personal data, it is your right to make a complaint to the data protection regulator. The regulator is the Information Commissioner’s Office:
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113 (local rate).
ICO Website: https://www.ico.org.uk